Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.
Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.
Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.
Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
Partner with engineering teams to validate fixes and implement long-term security improvements.
Define and maintain secure SDLC processes, including security reviews and threat modeling.
The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.
Assist with source code review and secure coding improvements.
Use SAST, DAST, and SCA tools to identify and validate vulnerabilities.
Collaborate with teams to integrate security into CI/CD and SDLC processes.
This company is a technology-driven healthcare organization integrating security into software development. It fosters a collaborative remote culture and supports professional growth in cybersecurity.
Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.
Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
Contribute to security architecture reviews and support bug bounty programs and incident response.
Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.
Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.
Conduct advanced offensive security research across cloud infrastructure (AWS, GCP), production services, internal tooling, and AI platforms.
Design and execute realistic adversary simulations targeting identity systems, cloud control planes, supply chains, and distributed architectures.
Research emerging attack vectors against LLMs, AI agents, retrieval systems, MCP integrations, prompt orchestration, and autonomous workflows.
This venture-backed AI company combines world-class human expertise with advanced machine learning workflows to help leading AI organizations build and improve cutting-edge models. Backed by over $40 million in funding and a rapidly expanding international network, it operates as a distributed, remote-first team.
Partner with product and engineering teams to identify risks early and build security into new features.
Lead threat modeling and secure design reviews for new products and architecture changes.
Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.
Represent the security organization in customer-facing incidents, cases, and security-related calls.
Own, triage, investigate, and respond to security matters, ensuring timely communication and resolution.
Act as the primary point of contact for security matters, supporting both internal and external stakeholders.
ServiceNow provides an AI platform for business reinvention, helping 85% of the Fortune 500 work smarter and faster. The company fosters an AI-native culture where technology and talent are unstoppable together.